← Back

CVE-2015-2713

nvd nist
Published: May 14, 2015Modified: May 6, 2026

JSON object

Loading...
6.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 8.6 / Impact: 6.4
Source: NVD

Description

Use-after-free vulnerability in the SetBreaks function in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a document containing crafted text in conjunction with a Cascading Style Sheets (CSS) token sequence containing properties related to vertical text.

Affected (20)

3 products
1 product
Opensuse
3 products
Firefox
Thunderbird
Firefox Esr
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Version 12.0
Version 12.0
Version 12.0
Opensuse
Version 13.1
Version 13.2
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 37.0.2
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 31.5
Configuration D
13 vulnerable
Vulnerable SoftwareAffected Versions
Mozilla
Version 31.0
Version 31.1.0
Version 31.1.1
Version 31.3.0
Version 31.5.1
Version 31.5.2
Version 31.5.3
Mozilla
Version 31.1
Version 31.2
Version 31.3
Version 31.4
Version 31.5
Version 31.6.0

References (34)

Source: security@mozilla.org
Vendor Advisory
Source: security@mozilla.org
Source: security@mozilla.org
Source: security@mozilla.org
Source: security@mozilla.org
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.